The Containment Era is here. →Explore

Executive Summary

In Q3 2025, the ransomware threat landscape reached unprecedented fragmentation with 85 active ransomware and extortion groups, including the high-profile resurgence of LockBit following international law enforcement takedowns. Attackers targeted organizations across sectors, leveraging decentralized affiliate models to rapidly launch new ransomware 'brands' — 14 of which debuted this quarter. Tactics included sophisticated lateral movement, exploit of unencrypted east-west traffic, and multifaceted extortion through leak sites. Over 1,590 public victim disclosures underscored the sustained operational tempo, with significant financial and reputational losses reported by victims.

This incident signals new urgency for defenders, as ransomware operations grow increasingly resilient and adaptive. The proliferation of new actor groups, coupled with a strong affiliate network and advanced techniques, means that traditional prevention strategies are being routinely bypassed, demanding adoption of modern security controls aligned to emerging frameworks and zero trust principles.

Why This Matters Now

The resurgence of LockBit and rapid emergence of new ransomware groups highlight a fundamental shift in the cybercrime ecosystem, making attacks more unpredictable and widespread. Organizations must urgently rethink vulnerability management, east-west traffic controls, and incident response as legacy measures fail to keep pace with attackers’ adaptability.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

This quarter saw a record 85 active groups and a rapid rebound by LockBit, indicating greater criminal decentralization and faster adaptation after takedowns.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Comprehensive zero trust segmentation, east-west control, and egress policy enforcement provided by CNSF could have detected or blocked lateral movement, command & control, and data exfiltration, severely limiting the blast radius and effectiveness of the ransomware attack. Enhanced visibility and anomaly detection would have enabled earlier incident response at every stage.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF) with Multicloud Visibility & Control

Mitigation: Early detection of anomalous access attempts and exposed services.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Policy-based limitation of lateral privilege escalation.

Lateral Movement

Control: East-West Traffic Security and Kubernetes Security (AKF)

Mitigation: Blocked unauthorized lateral traffic between workloads and within Kubernetes clusters.

Command & Control

Control: Inline IPS (Suricata) and Egress Security & Policy Enforcement

Mitigation: Detection and blocking of known C2 communication patterns and suspicious outbound traffic.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevention of unauthorized data transfers out of the environment.

Impact (Mitigations)

Rapid detection and response to malicious encryption behavior.

Impact at a Glance

Affected Business Functions

  • Operations
  • Customer Service
  • Finance
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive customer and financial data due to unauthorized access and data exfiltration.

Recommended Actions

  • Implement identity-based zero trust segmentation to restrict privilege escalation and lateral movement.
  • Deploy comprehensive east-west traffic controls and Kubernetes security to isolate workloads and clusters.
  • Enforce robust egress policies and inline IPS to detect/block C2 and exfiltration attempts.
  • Leverage continuous visibility and real-time anomaly detection for early warning and response.
  • Regularly review and update cloud firewall, encryption, and hybrid connectivity controls to reduce exposure.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image